CVE

CVE-2026-16583 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16583 Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.0.8 3.0.8 2026-07-27

CVE-2026-16583

The Orbit Fox plugin's SVG upload functionality allows authorized users to upload malicious SVG files, which can contain executable JavaScript code. This code executes when the uploaded file is viewed on the affected website, enabling a stored cross-site scripting vulnerability. The issue affects versions of the plugin prior to 3.0.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.